CySA+ v4 · Objective 1.2

Recognizing malicious activity

Evaluate suspicious network, host, application, cloud, and identity behaviour using corroborating evidence. Distinguish an indicator from a confirmed conclusion.

What you will be able to do

  • Explain competing causes of anomalous activity.
  • Correlate host and network indicators into a testable hypothesis.
  • Investigate identity and email anomalies without relying on a single signal.
  • Separate observed facts, interpretation, and confidence in a triage note.

Learn the concepts

  1. Lesson 1

    Reason from host and network indicators

    Indicators point towards questions. They become useful when you compare them with expected behaviour and seek independent evidence that could support or disprove your interpretation.

    Open lesson →
  2. Lesson 2

    Connect identities, applications, and email

    Compromise can appear as normal application functionality used by the wrong person. Identity and business context are therefore as important as endpoint detections.

    Open lesson →

Apply your judgement · Synthetic scenario

The payment-change conversation

A purchasing assistant receives a convincing reply in an existing supplier conversation. Soon afterwards the internal account opens files it rarely uses.

Email
Existing conversation; urgent bank-detail change; sender authentication passes
Sign-ins
08:10 corporate VPN; 08:14 unfamiliar network; location alert raised
Mailbox audit
08:16 new rule moves finance messages into an archive folder
File access
08:18 account downloads 64 supplier-contract files; normal daily range 0–4

Your task

  1. Separate the observed indicators from the conclusions they support.
  2. Choose two independent checks to distinguish compromise from legitimate work.
  3. Recommend immediate business and technical actions with verification.
Compare your response

The rule creation and unusual downloads strengthen an account-compromise hypothesis. The travel alert alone is inconclusive, and valid email authentication does not validate the payment change.

Confirm the payment instruction through an established contact, and compare the account sessions, device identities, and mailbox-rule creation with the assistant’s confirmed activity. Check whether the VPN explains the location difference.

Hold the bank-detail change and preserve messages and audit records. If compromise is supported, follow the account-response process for affected sessions and credentials, then verify removal of unauthorised rules and cessation of unusual access.

Put it into practice

Use these labs alongside this module.

Check your understanding

Choose the best response to each scenario, then check your reasoning. These are course practice questions.

1. A signed system utility reads many documents and launches an outbound transfer. Which evidence most improves interpretation?
2. An impossible-travel alert involves a known corporate VPN exit. What is the best next step?
3. A cloud service account unexpectedly creates expensive compute resources but no endpoint alert fires. Which response is best?

0 of 3 answered

Source reading: supplied book, chapters 3, 5. Lessons, scenarios, and questions are original CyberCorps course material.